Senior DevSecOps Engineer

Nextwebi

Bengaluru

On-site

INR 1,500,000 - 3,000,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Nextwebi in Bengaluru is seeking a Senior SecOps Engineer to join our security team. You will own offensive security initiatives, lead penetration testing activities, and foster a security-first culture across engineering teams.

This role combines AppSec with emerging AI security challenges. You will identify, assess, and address security risks across applications, cloud environments, APIs, and AI/LLM-powered systems, while collaborating with product teams to embed security throughout the

Qualifications

  • 4+ years in Security Engineering with at least 2 years in Penetration Testing.
  • Experience with AI/LLM security incl. prompt injection and MCP security assessments.
  • Strong web app and API pentesting, OWASP Top 10, auth bypasses.
  • Scripting in Python/Go/Bash for tool development and automation.
  • Cloud security across AWS, GCP or Azure; IAM, misconfigurations, lateral movement.
  • CI/CD security with SAST, DAST and SCA; secure coding practices.
  • Experience communicating security findings to technical and non-technical stakeholders.

Responsibilities

  • Lead and execute end-to-end penetration testing across web apps, APIs, and cloud.
  • Design red team exercises and perform threat modeling before deployment.
  • Develop exploits, scripts, and tools to improve coverage and repeatability.
  • Prepare clear penetration testing reports for engineers and management.
  • Coordinate with third-party testers and support responsible disclosure programs.
  • Research and test AI/LLM systems, including prompt injections and MCP security.
  • Work with ML and product teams to embed security throughout the development lifecycle.
  • Integrate security controls into CI/CD pipelines (SAST/DAST/SCA) and enforce secure coding standards.
  • Conduct risk assessments, maintain risk registers, and communicate risk posture.

Skills

Penetration testing
AI/LLM security
Web app security
Scripting

Tools

Python
Go
Bash
OWASP
SAST tooling
DAST tooling
SCA tooling
AWS
GCP
Azure

Job description

About the Role

We are looking for a skilled Senior SecOps Engineer to join our Security team. The ideal candidate will take ownership of offensive security initiatives, lead penetration testing activities, and contribute to building a strong security-first culture across engineering teams.

This role combines traditional Application Security (AppSec) with emerging AI security challenges. The candidate will work on identifying, assessing, and addressing security risks across applications, cloud environments, APIs, and AI/LLM-powered systems.

Key Responsibilities
Penetration Testing
  • Lead and execute end-to-end penetration testing across web applications, APIs, internal services, and cloud infrastructure.
  • Design and conduct red team exercises that simulate real-world adversarial scenarios.
  • Perform threat modeling for new product features and architectures before deployment.
  • Develop custom exploits, scripts, and tools to improve testing coverage and repeatability.
  • Prepare clear and actionable penetration testing reports for engineering teams and management.
  • Coordinate with third-party penetration testing vendors and support responsible disclosure programs.
AI & LLM Security
  • Research and perform security testing against AI/LLM-powered systems, including prompt injection, jailbreaks, indirect prompt injection through tool outputs, and data exfiltration through model responses.
  • Assess security risks in Model Context Protocol (MCP) deployments, including tool call boundaries, context poisoning vectors, and privilege escalation through agentic workflows.
  • Build and maintain an internal threat library for AI attack patterns and contribute to red‑teaming playbooks for LLM features.
  • Work closely with ML and product teams to integrate security throughout the AI feature development lifecycle.
DevSecOps
  • Integrate security controls into CI/CD pipelines, including SAST, DAST, SCA, secret scanning, and container scanning.
  • Define and enforce secure coding standards and security review processes across development teams.
  • Drive security automation initiatives to help engineering teams maintain development speed while reducing critical security vulnerabilities.
Risk Assessment
  • Assess and prioritize security risks across the organization using frameworks such as CVSS, DREAD, or FAIR.
  • Maintain and manage a risk register, track remediation progress, and communicate the overall risk posture to relevant stakeholders.
  • Evaluate security risks associated with third‑party vendors, integrations, and open‑source dependencies.
  • Assess and communicate the business impact of vulnerabilities to support effective remediation prioritization.
Compliance & Governance
  • Assist with security audits and gap assessments.
  • Support the development and maintenance of security policies, standards, and exception processes.
Required Skills & Experience
  • 4+ years of experience in Security Engineering, including at least 2 years of hands‑on experience in Penetration Testing.
  • Demonstrated experience with AI/LLM security, including prompt injection, model manipulation, or MCP security assessments.
  • Strong expertise in web application and API penetration testing, including OWASP Top 10, business logic flaws, and authentication bypasses.
  • Strong scripting skills in Python, Go, or Bash for developing custom security tools and automation.
  • Experience with cloud security across AWS, GCP, or Azure, including misconfigurations, IAM abuse, and lateral movement.
  • Familiarity with CI/CD security tools and integrating SAST, DAST, and SCA into development pipelines.
  • Experience in conducting risk assessments and communicating security findings to both technical and non‑technical stakeholders.
Good to Have
  • Bug bounty experience or CVE publications.
  • Experience with agentic AI frameworks such as LangChain, AutoGPT, or Claude Agents from a security testing or attacker's perspective.
  • Knowledge of compliance and security frameworks such as SOC 2, ISO 27001, and PCI‑DSS.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Senior Security Engineer
Senior Security Engineer

Nextwebi IT solutions Pvt ltd • Bengaluru

On-site
INR 2,500,000 - 4,500,000
Security & Compliance Engineer Intern
Security & Compliance Engineer Intern

AI Prof • Hyderabad

On-site
INR 1,500,000 - 2,100,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
AI Security Engineer
AI Security Engineer

QualiZeal • Hyderabad

On-site
INR 2,500,000 - 4,500,000
Application Security Specialist (AppSec + AI Security)
Application Security Specialist (AppSec + AI Security)

Qualizeal India • Hyderabad

On-site
INR 3,000,000 - 6,000,000
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Cornerstone • Mumbai, Pune District

On-site
INR 2,000,000 - 4,000,000
Sr Security Engineer I, Application Security
Sr Security Engineer I, Application Security

mpc • Bengaluru

On-site
INR 2,500,000 - 4,800,000
Sr Security Engineer I, Application Security
Sr Security Engineer I, Application Security

Flywire • Bengaluru

On-site
INR 3,500,000 - 5,500,000
Cyber Penetration Tester
Cyber Penetration Tester

Alignity Solutions • Hyderabad

On-site
INR 1,000,000 - 1,500,000